FBI, AHA warn of ‘OAuth consent phishing’ scheme

Advertisement

The FBI has issued a public service announcement warning of a cyberattack technique called “OAuth consent phishing” that lets hackers access victims’ accounts without stealing a password.

The scheme has been active since late 2025 and targets prominent individuals, their family members and personal acquaintances through direct messages on commercial messaging apps, the FBI said in early September. Attackers impersonate government officials, media figures or event coordinators, then send a malicious link disguised as a file-sharing service or event invitation.

When a victim clicks the link, they land on a legitimate-looking permission screen from a real cloud provider, such as Microsoft or Google. If the victim approves the request, they unknowingly grant a malicious application full access to read and send emails and access sensitive data — without ever handing over a password.

Because the access relies on an authorization token rather than login credentials, a password reset alone does not remove it. Victims must revoke the token directly in their account security settings to cut off the attacker’s access, according to the FBI.

The FBI advises increased scrutiny of messages from unfamiliar contacts and independent verification of any sender’s identity before granting app permissions.

The American Hospital Association’s John Riggi, national advisor for cybersecurity and risk, and Scott Gee, deputy national advisor for cybersecurity and risk, are directing member hospitals to the alert as the latest in a string of 2026 advisories on social engineering tactics targeting the healthcare sector.

Advertisement

Next Up in Cybersecurity

Advertisement